?
Solved

Exchange 2003 Server Queue Filling up!

Posted on 2012-12-27
6
Medium Priority
?
307 Views
Last Modified: 2012-12-28
I've read every article and have done practically everything. I've made sure there isn't an open relay, I've applied Recipient Filtering ( Checked "Filter recipients who are not in the Directory" ), Sender Filtering, Connection Filtering, Sender ID Filtering, I've gone to Default SMTP Virtual Server - Access - Relay and ticked "Only the list below" and unchecked "Allow all computers which successfully authenticate to relay regardless of the list above" as well as left the "Computer list" blank under "Only the list below",  I've disabled port 25 on the firewall, changed the admin password, disabled accounts that weren't being used, enabled logging on NDRs and haven't seen the event id 1708 (to see if another account has been compromised), enabled Tar Pit, I've tested to make sure it isn't a DNS problem, and disabled NDR....

I'm still continuing to get hundreds of thousands of NDRs from unrecognized email accounts in the queue. I have no idea what to do to solve this problem :-( If someone could please point me in the right direction I'd appreciate it!
0
Comment
Question by:stevegarri
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 20

Expert Comment

by:agonza07
ID: 38726157
Maybe they are not yours, maybe someone is just spoofing your email accounts and you're just getting the NDRs.

Check the headers on the NDR to see where they originated from. Might not be your IP.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 38726234
Does your server receive emails directly or via a 3rd party filter service?

If direct, trial Vamsoft (www.vamsoft.com) and the pain will go away.

I'm assuming the sender of the messages is Postmaster@yourdomain.local?

Alan
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38726721
Even after closing the holes, you will still see messages pile up for some time afterwards. When a server has been abused, the spammer will send 1000s of messages as quickly as possible and it takes time for Exchange to process them. I have seen email contiue to pile up for six or seven hours after the server was disconnected from the internet. You will just have to wait it out unfortuantely.

Simon.
0
Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

 

Author Comment

by:stevegarri
ID: 38726832
The email has been piling up for over 24 hours. Message ID is adsfdjkafh234223@mail.mydomain.com

Sender is noreply@mail.yahoo-inc.com or tw-edm-auction@yahoo-inc.com

I've been constantly having to use the aqadmcli.exe tool to clear the queue :-( It's so wierd and I can't figure out where they are coming from. Anyone have any idea how I can stop this?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 2000 total points
ID: 38726859
That is what happens.
There will be 1000s of messages that Exchange is still processing. What you see in the queue is just the tip of what could be inside Exchange still waiting to be processed.

Simon.
0
 

Author Closing Comment

by:stevegarri
ID: 38728390
Yup you were right. A few hours later it ended up leveling off and zero-ing out :-) Exchange is all good! Thanks!
0

Featured Post

WordPress Tutorial 4: Recommended Plugins

Now that you have WordPress installed, understand the interface, and know how to install new parts, let’s take a look at our recommended plugins.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
how to add IIS SMTP to handle application/Scanner relays into office 365.
Suggested Courses

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question